Skip to main content
v2026.11,772 entries · CC-BY 4.0

Direct comparison

Anonymization vs. Pseudonymization

Anonymization is irreversible and exits GDPR scope; pseudonymization is reversible and stays in scope. Compare techniques, legal basis, and use cases.

Written and maintained by CASRAI Editorial Board

Last updated

Ask CASRAI · included with Regulatory Radar

Ask about Anonymization vs. Pseudonymization

Ask CASRAI answers research-administration questions and cites the passages behind every claim — and says so when the corpus does not cover something, instead of guessing. It comes with a Regulatory Radar subscription at $29 a month, alongside the daily digest of regulatory changes and the dashboard of what changed.

150 questions a day, on this site, over the API, or inside your own tools through the CASRAI MCP server.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

How do Anonymization, Pseudonymization compare side by side?

The table below compares Anonymization, Pseudonymization across 10 procurement-relevant dimensions, from what it does through risk if done incorrectly.

Side-by-side comparison

DimensionAnonymizationPseudonymization
What it doesIrreversibly removes or alters identifying informationReplaces identifiers with a code/token; original identity recoverable via a separately-held key
ReversibilityNot reversible, by definitionReversible by anyone with access to the key file
GDPR statusFalls outside GDPR scope entirely (Recital 26) once genuinely anonymousRemains personal data — GDPR still applies in full (Article 4(5), Recital 26)
GDPR basisNot defined as a processing operation with its own article; outcome described in Recital 26Defined in Article 4(5); named as a research safeguard in Article 89(1)
Re-contacting participantsNot possible — no link back to identity existsPossible via the key file, subject to access controls
Typical techniquesSuppression, generalization, perturbation, k-anonymity, differential privacy, synthetic dataCoded/tokenized identifiers, encryption with a separately-stored key, linkage tables
Key file / crosswalkNone exists — destroyed or never createdExists, stored separately with access controls
Comparable US standardHIPAA Safe Harbor / Expert Determination (45 CFR 164.514(a)-(b)) removes data from PHI scopeNo exact HIPAA equivalent — coded data with a retrievable key generally remains PHI
When typically used in researchPublic repository deposit, long-term archiving, once re-contact is no longer neededActive data collection and analysis, when re-contact or correction may be needed
Risk if done incorrectlyRe-identification via combination with other datasets (quasi-identifier linkage)Key file exposure or weak access controls defeat the protection

Common questions

Common questions about Anonymization vs Pseudonymization

Is pseudonymized data still personal data under GDPR?

+

Yes. GDPR Recital 26 states that pseudonymised data which could be attributed to a person using separately-held additional information is still considered information on an identifiable natural person, so it remains fully within GDPR's scope.

Can anonymized data be re-identified later?

+

If it truly meets the anonymization standard, no — by definition, re-identification must not be possible by any means reasonably likely to be used, accounting for cost, time, and available technology. If a dataset can later be re-identified by reasonably available means, it was not properly anonymized in the first place.

Does deleting the key file turn pseudonymized data into anonymized data?

+

It can move it toward anonymization, but only if no other reasonably available means of re-identification remain — for example, no other copy of the key exists anywhere, and the data cannot be re-linked by combining it with other accessible datasets. This should be assessed and documented, not assumed.

Which one should a data management plan specify?

+

State explicitly which technique is used at which stage — for example, pseudonymized during active collection and analysis, anonymized before public deposit — rather than using the terms interchangeably. Funders and ethics boards increasingly expect this level of specificity.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 72,264 indexed passages, and every answer cites the ones it drew on.